Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All tutorials
    • Differentiation of access permissions for user groups
    • Service account with an OS Login profile for VM management via Ansible
      • Overview
      • 1C:Enterprise
      • Grafana OSS
      • Harbor
      • Managed Service for GitLab
      • Managed Service for OpenSearch
      • MWS
      • NetBird
      • OpenSearch
      • Selectel
      • Sentry
      • SonarQube
        • SAML
        • OpenID Connect
      • VK Cloud
      • Zabbix
      • Passwork
      • Yandex 360
      • Yandex Browser for organizations
      • Using OAuth2 Proxy for applications not supporting SSO
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Create an app
  • Set up the integration
  • Get the application's credentials and create a secret for it
  • Set up OIDC authentication in Time
  • Configure a redirect URI in Yandex Identity Hub
  • Add users
  • Make sure your application works correctly
  1. Tutorials
  2. Setting up single sign-on (SSO) for apps
  3. Time
  4. OpenID Connect

Creating an OIDC app in Yandex Identity Hub for integration with Time

Written by
Yandex Cloud
Updated at September 1, 2026
View in Markdown
  • Create an app
  • Set up the integration
    • Get the application's credentials and create a secret for it
    • Set up OIDC authentication in Time
    • Configure a redirect URI in Yandex Identity Hub
  • Add users
  • Make sure your application works correctly

Time is a corporate messenger with single sign-on support based on the OpenID Connect (OIDC) standard.

For your organization's users to be able to authenticate to Time via OpenID Connect SSO, create an OIDC app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Time.

OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.

To provide your organization's with access to Time:

  1. Create an app.
  2. Set up the integration.
  3. Add users.
  4. Make sure the application works correctly.

Create an appCreate an app

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select  Apps.
  3. In the top-right corner, click Create application and in the window that opens:
    1. Select the OIDC (OpenID Connect) single sign-on method.
    2. In the Application type field, select Web Application.

      OIDC apps of the Web Application type are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see Types of OIDC apps in Yandex Identity Hub.

    3. In the Name field, specify a name for your new app: time-oidc-app.
    4. In the Folder field, select the folder where you want to create an OAuth client for your app.
    5. Optionally, add a description and labels for the app.
    6. Click Create application.

Set up the integrationSet up the integration

To configure Time integration with the OIDC app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in Time.

Get the application's credentials and create a secret for itGet the application's credentials and create a secret for it

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, click Apps and select =time-oidc-app.
  3. On the Overview tab, under Identity provider (IdP) configuration, copy the ClientID setting value.
  4. Create an app secret (only available for applications of the Web Application type):

    1. Under App secrets, click Add secret, and in the window that opens:

      1. Optionally, add a description for the new secret.
      2. Click Create.

    The window will display the generated application secret. Save this value.

    Warning

    If you refresh or close the application information page, you will not be able to view the secret again.

    If you closed or refreshed the page before saving the secret, click Add secret to create a new one.

    To delete a secret, in the list of secrets on the OIDC app page, click in the secret row and select Delete.

Set up OIDC authentication in TimeSet up OIDC authentication in Time

  1. Log in to the Time system console at https://<instance_name>.time-messenger.ru/admin_console/authentication/openid, where <instance_name> is the name of your Time instance.
  2. Under Authentication:
    1. Select OpenID Connect.
    2. Under Select provider, select OpenID connection (Other).
    3. Optionally, in the Button name field, enter the text that appears on the login button on the login page, e.g., Via OIDC.
    4. Optionally, select a color for the login page button.
    5. In the Issuer link field, enter the OpenID Connect provider's address: https://auth.yandex.cloud.
    6. In the Client ID field, enter the ClientID value you copied from Yandex Identity Hub.
    7. In the Client key field, specify the application secret generated in Yandex Identity Hub.
  3. Save the settings.

Configure a redirect URI in Yandex Identity HubConfigure a redirect URI in Yandex Identity Hub

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, click Apps and select time-oidc-app.
  3. At the top right, click Edit and in the window that opens:
    1. In the Redirect URI field, specify this callback address: https://<instance_name>.time-messenger.ru/signup/openid/complete, where <instance_name> is the name of the Time instance (subdomain at time-messenger.ru).
    2. Under OAuth/OIDC security, disable the Require PKCE option so that Yandex Identity Hub does not require the external application to use the PKCE security extension when exchanging data.

      PKCE is a security extension used in OAuth 2.0 to minimize the risk of authentication data interception. For more information, see PKCE.

    3. Click Save.

Add usersAdd users

To authenticate with Time, add the required users and/or user groups to your Yandex Identity Hub OIDC application.

Note

Users and groups added to an OIDC application can be managed by any user with the organization-manager.oidcApplications.userAdmin role or higher.

To add users to a SAML application:

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, click Apps and select time-oidc-app.
  3. Navigate to the Users and groups tab.
  4. Click Add users.
  5. In the window that opens, select the required users.
  6. Click Add.

Tip

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.

Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.

Make sure your application works correctlyMake sure your application works correctly

To ensure that your OIDC application and integration with Time are working correctly, log in to Time as one of the added users. Proceed as follows:

  1. In your browser, open the login page of your Time instance: https://<instance_name>.time-messenger.ru.
  2. Select login via OpenID Connect.
  3. Authenticate in Yandex Cloud under a user account from your organization.
  4. Make sure you have signed in to Time following a successful authentication.

Was the article helpful?

Previous
SAML
Next
OpenVPN Access Server
© 2026 Direct Cursus Technology L.L.C.